<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic being dropped by Anti Malware in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189443#M34855</link>
    <description>&lt;P&gt;Search either via SmartView or in SmartViewTracker. The latter is a legacy application available with your SmartConsole installation package. You will need to go to the SmartConsole program folder and find it.&lt;/P&gt;</description>
    <pubDate>Mon, 14 Aug 2023 13:57:07 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2023-08-14T13:57:07Z</dc:date>
    <item>
      <title>Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189396#M34839</link>
      <description>&lt;P&gt;I'm troubleshooting a problem with users unable to log into the backblaze website. It reports an issue fetching the account however if I switch to a broadband connection it works fine!&lt;/P&gt;&lt;P&gt;Checking the logs I see nothing being blocked, however when I run a zdebug I see the following:&lt;/P&gt;&lt;P&gt;@;1564707902;[cpu_6];[fw4_2];fw_log_drop_ex: Packet proto=6 10.110.0.10:62707 -&amp;gt; 62.0.58.94:443 dropped by fw_handle_first_packet Reason: Anti Malware;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first confusing thing is the destination IP appears to belong to Checkpoint.&lt;/P&gt;&lt;P&gt;The Threat prevention policy is set to Optimised but the IPS blade is not enabled (in fact at present only the anti-bot and anti-virus blades are enabled. (not idea I know but this is a temporary measure) Also note that HTTPS inspection is not enabled at present either)&lt;/P&gt;&lt;P&gt;I've tried creating a new rule for the machine in question, disabling all threat prevention, but the issue remains.&lt;/P&gt;&lt;P&gt;Any assistance would be appreciated!&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 11:18:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189396#M34839</guid>
      <dc:creator>Steve_Pearson</dc:creator>
      <dc:date>2023-08-14T11:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189405#M34842</link>
      <description>&lt;P&gt;Can you find the corresponding logs? It might be, for example, the GW is checking SNI for that server and founds it a malware site. What do the AB logs say?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 11:52:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189405#M34842</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-14T11:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189409#M34843</link>
      <description>&lt;P&gt;Hi Val,&lt;/P&gt;&lt;P&gt;There are no logs that I can find for this, I've checked in the main logs, and also logs for the AB and the AM blades, I'm only seeing the drops when running a zdebug.&lt;/P&gt;&lt;P&gt;Out of interest, if I try to login from my laptop running the full Harmony Endpoint suite connected to broadband, there are no problems, which indicates that the site is ok. So the issue is only when the connection is going via the gateway.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 12:22:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189409#M34843</guid>
      <dc:creator>Steve_Pearson</dc:creator>
      <dc:date>2023-08-14T12:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189410#M34844</link>
      <description>&lt;P&gt;Ok, I know this may sound extreme thing to try, specially during work hours, but to be 100% sure, are you able to disable anti-bot and install policy? If that works, then we are positive something within that blade is causing it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 12:34:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189410#M34844</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-14T12:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189417#M34845</link>
      <description>&lt;P&gt;Look at the raw logs, search by source and destination. It is extremely unlikely there are no logs at all.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 12:42:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189417#M34845</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-14T12:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189437#M34852</link>
      <description>&lt;P&gt;I've never tried viewing the raw logs, are you able to advise how I do this please? (I know where they are stored!)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 13:37:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189437#M34852</guid>
      <dc:creator>Steve_Pearson</dc:creator>
      <dc:date>2023-08-14T13:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189439#M34853</link>
      <description>&lt;P&gt;That is extreme, but it would certainly prove that the AB blade is the culprit!&lt;/P&gt;&lt;P&gt;I'll try this later tonight if I can.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 13:38:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189439#M34853</guid>
      <dc:creator>Steve_Pearson</dc:creator>
      <dc:date>2023-08-14T13:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189442#M34854</link>
      <description>&lt;P&gt;I agree, BUT, here is good news...even if you disable the blade and install policy, it would NOT wipe out any existing settings, rules, si easy to put it all back after, just re-enable the and install the policy again.&lt;/P&gt;
&lt;P&gt;Personally, I would still make sure I have screenshots of all the existing things related to AB...better be on the safe side.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 13:54:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189442#M34854</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-14T13:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189443#M34855</link>
      <description>&lt;P&gt;Search either via SmartView or in SmartViewTracker. The latter is a legacy application available with your SmartConsole installation package. You will need to go to the SmartConsole program folder and find it.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 13:57:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189443#M34855</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-14T13:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189448#M34856</link>
      <description>&lt;P&gt;I agree 100%, record the settings first!&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 14:12:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189448#M34856</guid>
      <dc:creator>Steve_Pearson</dc:creator>
      <dc:date>2023-08-14T14:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189453#M34857</link>
      <description>&lt;P&gt;Sorry, I didn't realise that you were referring to SmartView when you said to look at the raw logs.&lt;/P&gt;&lt;P&gt;I can't find Smartview Tracker in the SmartConsole folders at all.&lt;/P&gt;&lt;P&gt;SmartView runs but returns an error - Query failed. This is before I even type a query, and for anything I type. I suspect that this may relate to SmartEvent not being enabled? The reason for this is that we are recovering from an incident, so currently running with on box management on a 5800 applicance, and disk space is limited.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 14:31:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189453#M34857</guid>
      <dc:creator>Steve_Pearson</dc:creator>
      <dc:date>2023-08-14T14:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189460#M34859</link>
      <description>&lt;P&gt;While you are fixing your SmartLog, here is the SmartView Tracker&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-08-14 at 17.19.16.png" style="width: 769px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22056i02D112181B7BEF1D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-08-14 at 17.19.16.png" alt="Screenshot 2023-08-14 at 17.19.16.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 15:22:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189460#M34859</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-14T15:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189473#M34872</link>
      <description>&lt;P&gt;Thanks for that!&lt;/P&gt;&lt;P&gt;Running this and filtering by the users IP I see nothing more that the logging in Smartconsole unfortunately, but zdebug still shows the drops.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 16:40:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189473#M34872</guid>
      <dc:creator>Steve_Pearson</dc:creator>
      <dc:date>2023-08-14T16:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189475#M34873</link>
      <description>&lt;P&gt;Thats odd, as normally, when someone has issues with log indexing, logs show perfectly fine from old school SV tracker, as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;pointed out in his screenshot.&lt;/P&gt;
&lt;P&gt;So, you dont see anything more from there either?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 16:44:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189475#M34873</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-14T16:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189476#M34874</link>
      <description>&lt;P&gt;No I don't, there is just some http and https traffic in the logs, but nothing going to the address that zdebug is showing, which I beleive is a Checkpoint IP address!&lt;/P&gt;&lt;P&gt;I've now also tried an fwmonitor for a short time whilst I tested the login process, but it only sees the packets that zdebug is dropping.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 17:11:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189476#M34874</guid>
      <dc:creator>Steve_Pearson</dc:creator>
      <dc:date>2023-08-14T17:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189477#M34875</link>
      <description>&lt;P&gt;Maybe not related to you directly, but I would give this a go&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk123075" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk123075&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;fw ctl set int mal_conns_dep_limit 0&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 17:15:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189477#M34875</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-14T17:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189511#M34888</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23369"&gt;@Steve_Pearson&lt;/a&gt;&amp;nbsp;That's odd. I advise you to open a TAC case for this: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 10:26:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189511#M34888</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-15T10:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189523#M34898</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Did you end up disabling AB blade to see if it makes any difference?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 13:04:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189523#M34898</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-15T13:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189543#M34909</link>
      <description>&lt;P&gt;The default value for DNS trap IP is 62.0.58.94&lt;/P&gt;&lt;P&gt;more detail here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk74060" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk74060&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;It may be a query from your DNS server that is triggering anti malware/anti bot blade to return the DNS trap IP, instead of the real backblaze IP address.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 15:25:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189543#M34909</guid>
      <dc:creator>Lloyd_Braun</dc:creator>
      <dc:date>2023-08-15T15:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic being dropped by Anti Malware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189583#M34925</link>
      <description>&lt;P&gt;Hi, sorry for the slow reply, I work remotely and had no connection all day yesterday (drunk driver hit a telegraph pole!)&lt;/P&gt;&lt;P&gt;I did disable the AB blade an Monday night, and it resolved this issue, so that was a good move.&lt;/P&gt;&lt;P&gt;I then re-enabled it and tested again and it still worked!&lt;/P&gt;&lt;P&gt;I cleared the cache and rebooted the test pc, it still worked.&lt;/P&gt;&lt;P&gt;Couldn't do anything yesterday, tested again today and it's stopped working again!&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 09:14:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-being-dropped-by-Anti-Malware/m-p/189583#M34925</guid>
      <dc:creator>Steve_Pearson</dc:creator>
      <dc:date>2023-08-16T09:14:23Z</dc:date>
    </item>
  </channel>
</rss>

